Skip to content
Code Recycle

Component · for humans & their agents

Knowledge-Graph Merge

verified · first-partyactively maintained$0 during beta (was $39)

Two extractors disagree about the same entity. The naive merge is a spread, the last writer wins, and the only evidence anything was lost is that the answer changed.

by saltyhash · Code Recycle admin

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Verified: 25 tests · 10/10 mutations caught

Every system that extracts facts from documents eventually writes the same entity twice — two emails, two PDFs, two extractors, a human typing over the top.

The failure it prevents

Every system that extracts facts from documents eventually writes the same entity twice — two emails, two PDFs, two extractors, a human typing over the top.

The naive merge is `{...existing, ...incoming}`. The last writer wins, so a low-confidence guess pulled from a page-three footer silently overwrites a fact a person entered by hand. Nothing errors. Nothing logs. The only trace is that the answer is different now.

The rules it enforces

1. Aliases and source references are append-only. Evidence accumulates; a merge never trades it away. 2. High confidence is never overwritten by low. 3. Human-entered data outranks any extractor — and `createdBy` is immutable, because a later automated write that relabels the record would switch the rule off for exactly the rows it exists for. 4. A real disagreement is recorded, not resolved. Two high-confidence sources that differ keep the existing value and append a conflict record for a human. 5. Confidence is monotonically non-decreasing. One low-confidence touch cannot downgrade a well-attested node out from under everything that thresholds on it. 6. Visibility narrows, never widens. The most restrictive wins — the one rule here with a disclosure consequence, so it fails closed. 7. A pinned node still accumulates provenance. Declaring a node canonical freezes its name and properties, not the evidence trail that lets anyone check it.

Your ontology, not ours

Node and edge type vocabularies are plain strings. None of the merge rules read them — a conflict between two confidence values resolves the same whether the node is a person or a parcel — so you narrow them in your own code instead of adopting someone else's nouns.

What it does not do

It does not decide that two different ids are the same entity; resolution is a separate problem, and it throws on an id or type mismatch rather than welding two entities together. And it does not resolve conflicts — it records them. A merge that adjudicates disputed facts on its own is the thing this replaces.

Verified

25 tests, and 10 deliberate defects applied to the real source — all 10 caught, including last-write-wins, widening visibility, a rewritten `createdBy`, and conflicts computed and then dropped on the floor. The set ships in the source.

Delivery

Source delivered as a private repository invite within 24 hours of purchase. Single-product commercial license: use and modify in any number of products; no redistribution or resale of the source.

Interface

What you call, and what comes back. Types and signatures only — the implementation ships with the source.

  export function mergeGraphNodes( existing: GraphNodeShape, incoming: GraphNodeWrite, now: Date = new Date(), opts?:;
  export function mergeGraphEdges( existing: GraphEdgeShape, incoming: GraphEdgeWrite, now: Date = new Date(), ): GraphEdgeShape;

01Capabilities

Does

  • + Audit logs
  • + Entity resolution
  • + Duplicate and sybil detection

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

typescript

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

0 open · 0 answered · 0 fixed · 1 said it worked

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Verified · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across 8 source file(s) plus listing text
  • capability contract All 0 observed capability reference(s) match the declared manifest
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
1.0.0stableAug 10, 2026First public release.